Impact
The PublishPress Authors plugin for WordPress contains a stored cross‑site scripting flaw. An authenticated user with Author or greater privileges can insert arbitrary JavaScript into the profile_fields_user_email_value_prefix parameter, which is saved into the database and rendered in the author box. When a site visitor views the author box, the malicious code executes in that visitor’s browser, enabling session hijacking, phishing, or site defacement within the affected WordPress site.
Affected Systems
WordPress sites that have the PublishPress Authors plugin installed, specifically versions 4.15.0 and all earlier releases, and where the author box module is enabled, are susceptible to this vulnerability. Any user with Author+ access who has not been sanctioned by site administrators is a potential attacker.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating moderate. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated author or higher user to modify the vulnerable field; thereafter the script is delivered to any on‑site user who views the author box, with the attack achieved through the lack of proper input sanitization and output escaping.
OpenCVE Enrichment